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Amendments to the Claims 

Please amend Claims 1, 33, 36, and 38 as follows, without prejudice or disclaimer to 
continued examination on the merits: 

1. (Currently Amended): A method for mapping the topology of a wireless network, 
the method comprising the steps of: 

(a) receiving scan data comprising information collected from IEEE 802.11 
management and control wireless local area network frames transmitted on the wireless 
network, wherein the received scan data is received from a wireless sensor configured to 
monitor the wireless network and collect information from frames transmitted on the 
wireless network, wherein the scan data is associated with monitoring of one or more 
wireless access points, one or more wireless network nodes or combinations thereof, and 
wherein the wireless network comprises a wireless local area network; 

(b) identifying a relationship (1) between at least one of the wireless access points 
and at least one of the wireless network nodes or (2) between any two wireless network 
nodes based on the received scan data, a characteristic of at least one of the wireless access 
points, a characteristic of at least one of the wireless network nodes or combinations 
thereof, wherein the relationship is identified responsive to an analysis of the scan data and 
responsive to a relationship between the wireless sensor and a server; 

(c) storing the identified relationship, access point characteristic, node 
characteristic or combinations thereof in a system data store as topology data; 

(d) formatting the stored topology data based upon a desired output format; and 

(e) repeating steps (a) through (d) a plurality of times, wherein the system data 
store stores topology data for each repetition, and wherein potential security and policy 
violations are detected responsive to historical topology data. 

2. (Original): The method of claim 1, and further comprising the step of initiating one or 
more scans of wireless transmissions to generate the scan data. 
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3. (Original): The method of claim 2, wherein the step of initiating one or more scans 
comprises initiating a plurality of scans. 

4. (Original): The method of claim 3, wherein each of the plurality of scans is initiated 
upon a different wireless sensor. 

5. (Original): The method of claim 4, wherein each of the plurality of scans occurs 
simultaneously. 

6. (Original): The method of claim 4, and further comprising the step of repeating the step 
of initiating the plurality scans. 

7. (Original): The method of claim 6, wherein the repetition step occurs over a particular 
time period. 

8. (Original): The method of claim 7, and further comprising the step of determining the 
particular time period based upon configuration data, network security threat level, current 
network activity, historical network activity or combinations thereon. 

9. (Original): The method of claim 3, wherein each of the plurality of scans occurs within 
a particular time period. 

10. (Original): The method of claim 9, and further comprising the step of determining the 
particular time period based upon configuration data, network security threat level, current 
network activity, historical network activity or combinations thereof. 

11. (Original): The method of claim 2, and further comprising the step of receiving a 
mapping request from a user or a computer and wherein the scan initiation step is 
responsive to the received mapping request. 
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12. (Original): The method of claim 2, wherein the one or more initiated scans are initiated 
continuously or at periodic intervals. 

13. (Canceled) 

14. (Canceled) 

15. (Previously Presented): The method of claim 1, and further comprising the step of (f) 
storing the formatted topology data in a data store accessible by a server system. 

16. (Original): The method of claim 15, wherein the server system is an HTTP server, a 
WAIS server, a gopher server, or an FTP server. 

17. (Previously Presented): The method of claim 1, wherein the desired output format is 
TIFF, GIF, JPEG, HTML, SMS, MIME, S/MIME, ZIP, SML, SGML, WAP, BMP or 
combinations thereof. 

18. (Previously Presented): The method of claim 1, and further comprising the step of 
receiving a mapping request and wherein the formatting step is responsive to the received 
mapping request. 

19. (Original): The method of claim 18, wherein the mapping request is received from a 
user or a computer system. 

20. (Previously Presented): The method of claim 1, and further comprising detecting a 
mapping trigger event based upon the received scan data and wherein the formatting step is 
responsive to the detected trigger event. 

21. (Original): The method of claim 20, wherein the trigger event is a usage volume 
anomaly, a connectivity pattern anomaly, a policy violation, a security violation or 
combinations thereof. 
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22. (Previously Presented): The method of claim 1, and further comprising the step of (f) 
transmitting the stored topology data to a desired output device. 

23. (Previously Presented): The method of claim 22, and further comprising the step of 
repeating steps (a) through (f) a plurality of times. 

24. (Previously Presented): The method of claim 22, and further comprising the steps of 
(g) determining a desired output format and (h) formatting the stored topology data based 
upon the desired output format prior to transmission. 

25. (Original): The method of claim 24, wherein the step of determining the desired output 
format comprises the step of determining the desired output format based upon 
configuration data, the desired output device, a mapping request or combinations thereof. 

26. (Previously Presented): The method of claim 22, and further comprising the step of 
(g) determining the desired output device. 

27. (Previously Presented): The method of claim 26, wherein step (g) comprises the step 
of determining the desired output device based upon configuration data, a mapping request 
or combinations thereof 

28. (Original): The method of claim 22, wherein the desired output device is a monitor, a 
printer, a further processing system, a pager, a telephone, a personal data assistant (PDA), 
an e-mail account or a combination thereof. 

29. (Previously Presented): The method of claim 22, wherein the desired output device is 
capable of rendering graphical output and further comprising the step of (g) formatting the 
topology data in a manner to graphically represent characteristics or relationships prior to 
transmission; 
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wherein the graphically represented characteristics or relationships comprise 
whether a wireless access point of the one or more wireless access points is authorized, 
unauthorized, or ignored and whether a wireless network node of the one or more wireless 
network nodes is authorized, unauthorized, unassociated, an adhoc station, or ignored. 

30. (Previously Presented): The method of claim 29, wherein the desired output device is 
capable of rendering color output and wherein the formatting step (g) comprises the step of 
formatting the topology data in manner using color to represent characteristics or 
relationships prior to transmission. 

3 1 . (Previously Presented): The method of claim 22, wherein the desired output device is 
capable of rendering color output and further comprising the step of (g) formatting the 
topology data in manner using color to represent characteristics or relationships prior to 
transmission. 

32. (Original): The method of claim 1, and further comprising the step of identifying a 
relationship between a plurality of the wireless nodes based on the received scan data in 
which no wireless access point is involved. 

33. (Currently Amended): A system for mapping the topology of a wireless network, 
the system comprising: 

(a) storage means for storing topology data comprising access point characteristic 
data, wireless network node characteristic data, access point to node relationship data, node 
to node relationship data or combinations thereof; 

(b) a wireless sensor for scanning wireless transmissions within a wireless network 
and generating scan data therefrom, wherein the scan data comprises information collected 
from IEEE 802.11 management and control wireless local area network frames transmitted 
on the wireless network, wherein the wireless sensor operates in a promiscuous mode, and 
wherein the wireless network comprises a wireless local area network; 

(c) receiving means for receiving scan data from the wireless sensor over one of a 
wireless and wired connection; 
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(d) analysis means for generating topology data by identifying from scan data 
received by the receiving means a characteristic of a wireless network node, a 
characteristic of an access point, a characteristic of the wireless sensor, an access point to 
node relationship, a node to node relationship, an access point to sensor relationship, a 
node to sensor relationship, or combinations thereof and for storing the generated topology 
data in the storage means; 

(e) output means for formatting topology data generated by the analysis means 
based upon a desired output format and for transmitting the formatted topology data to a 
desired output device; and 

(f) topology comparison means for comparing historical topology data to evaluate 
potential wireless local area network security and policy violations of the wireless network. 

34. (Previously Presented): The system of claim 33, further comprising intrusion 
detection means for detecting a usage volume anomaly, a connectivity pattern anomaly, a 
policy violation, a security violation or combinations thereof, and wherein the output 
means is responsive to a mapping request from a trigger event from the intrusion detection 
means. 

35. (Previously Presented): The system of claim 33, further comprising intrusion 
detection means for detecting a usage volume anomaly, a connectivity pattern anomaly, a 
policy violation, a security violation or combinations thereof, and wherein the wireless 
sensor monitors responsive to a mapping request from a trigger event from the intrusion 
detection means. 

36. (Currently Amended): A system for mapping the topology of a wireless network, 
the system comprising: 

(a) a system data store (SDS) capable of storing topology data comprising access 
point characteristic data, wireless network node characteristic data, access point to node 
relationship data, node to node relationship data or combinations thereof; 
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(b) a system processor comprising one or more processing elements, wherein the 
system processor is in communication with the SDS and wherein the one or more 
processing elements are programmed or adapted at least to: 

(1) initiate at least one scan of one or more wireless access points, one or more 
wireless network nodes or combinations thereof, wherein the at least one scan is performed 
by a wireless sensor configured to monitor the wireless network and collect information 
from IEEE 802.11 management and control wireless local area network frames transmitted 
on the wireless network; 

(2) receive scan data comprising information collected from frames transmitted on 
the wireless network, and wherein the scan data is associated with monitoring of one or 
more wireless access points, one or more wireless network nodes or combinations thereof; 

(3) identify a relationship (i) between at least one of the wireless access points and 
at least one of the wireless network nodes or (ii) between any two wireless network nodes 
based on the received scan data, a characteristic of at least one of the wireless access 
points, a characteristic of at least one of the wireless network nodes or combinations 
thereof, wherein the relationship is identified responsive to an analysis of the scan data and 
responsive to a relationship between the wireless sensor and a server; 

(4) store the identified relationship, access point characteristic, node characteristic 
or combinations thereof in the SDS as topology data; and 

(5) format topology data generated based upon a desired output format; and 

(6) output the formatted topology data to a desired output device; 

(c) a wireless receiver that monitors wireless transmissions, wherein the wireless 
receiver is in communication with the system processor and wherein-the system 
processor's programming or adaptation to initiate at least one scan includes at least 
programming or adaptation to initiate the scan using the wireless receiver and wherein its 
programming or adaptation to receive scan data includes at least programming or 
adaptation to receive scan data from the wireless receiver or from an interface therewith; 
and 

(d) an intrusion detection engine configured to detect a usage volume anomaly, a 
connectivity pattern anomaly, a policy violation, a security violation or combinations 
thereof; 
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wherein an iteration of steps (1) through (6) is initiated responsive to the intrusion 
detection engine detecting a violation; and 

wherein the wireless network comprises a wireless local area network. 

37. (Canceled) 

38. (Currently Amended): One or more computer-readable media storing instructions 
that upon execution by a system processor cause the system processor to map the topology 
of a wireless network by performing at least the steps comprising of: 

(a) initiating a scan of one or more wireless access points, one or more wireless 
network nodes or combinations thereof, wherein the scan is performed by a wireless sensor 
configured to monitor the wireless network and collect information from frames 
transmitted on the wireless network, and wherein the wireless network comprises a 
wireless local area network; 

(b) receiving scan data comprising information collected from IEEE 802.11 
management and control wireless local area network frames transmitted on the wireless 
network, wherein the scan data is associated with monitoring of one or more wireless 
access points, one or more wireless network nodes or combinations thereof; 

(c) identifying a relationship (i) between at least one of the wireless access points 
and at least one of the wireless network nodes or (ii) between any two wireless network 
nodes based on the received scan data, a characteristic of at least one of the wireless access 
points, a characteristic of at least one of the wireless network nodes or combinations 
thereof, wherein the relationship is identified responsive to an analysis of the scan data and 
responsive to a relationship between the wireless sensor and a server; 

(d) storing the identified relationship, access point characteristic, node 
characteristic or combinations thereof as topology data; and 

(e) formatting topology data generated based upon a desired output format; 

(f) outputting the formatted topology data to a desired output device; and 

(g) comparing the topology data to historical topology data to evaluate potential 
security and policy violations of the wireless network. 
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39. (Previously Presented): The method of claim 1, further comprising determining, 
from the scan data, wireless local area network configured properties for the at least one of 
the wireless access points. 

40. (Previously Presented): The method of claim 39, wherein the wireless local area 
network configured properties comprise any of MAC address, access point name, 
Extended Service Set ID, supported wireless local area network rates, authentication 
modes, and wireless local area network encryption. 

41. (Previously Presented): The method of claim 1, further comprising determining 
MAC addresses on all stations within the at least one of the wireless access points' Basic 
Service Set. 
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